Evidence-backed facts
- Redis documents a trusted-client and trusted-environment security model and warns against directly exposing its service to untrusted networks. informative
- ACL users can be restricted by commands and keys, so successful authentication must not be treated as unrestricted read access. informative
- Write and administrative commands require separate least-privilege ACL decisions; dangerous configuration and destructive commands must not be exposed by default. informative
- Authentication, protected mode, persistence, replication, backup, and encryption are separate controls; a reachable endpoint is not evidence that any is correctly enabled. informative